Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Aligning on behavior of prefetch #723

Closed
noamr opened this issue Dec 18, 2022 · 4 comments
Closed

Aligning on behavior of prefetch #723

noamr opened this issue Dec 18, 2022 · 4 comments

Comments

@noamr
Copy link

noamr commented Dec 18, 2022

Request for Mozilla Position on changes to an Existing Web Specification

Mozilla introduced prefetch years ago... Now trying to align it across browsers. The proposal is very similar to what Mozilla already does, with a couple of changes:

Other information

@martinthomson
Copy link
Member

@bgrins, @mystor, this looks reasonable to me. WDYT?

@tantek tantek changed the title Aligning on behavior of prefeetch Aligning on behavior of prefetch Dec 19, 2022
@smaug----
Copy link
Collaborator

Looks reasonable to me too.

@noamr
Copy link
Author

noamr commented Dec 20, 2022

Thanks! I wonder what's your view on the related CSP change: w3c/webappsec-csp#582
Tl;dr: instead of having a custom prefetch-src, we use default-src or the least restrictive directive in the policy. This allows using resource hints and exfiltration protection (e.g. default-src 'none') together.

@zcorpan
Copy link
Member

zcorpan commented Jan 10, 2023

I've discussed with @valenting , we think this looks reasonable. Will label as "positive", no need for a dashboard entry.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants